Stop the bleeding. Prove the fix.
You define the boundaries for AI data egress. Tether enforces them deterministically at the endpoint and generates cryptographically signed proof for every decision.
Built for compliance.
A security control is only as good as the evidence it provides. We built Tether for the auditor.
Full payload and attribution
Capture the prompt, the response, the exact identity of the sender, the specific developer tool used, and the host machine—all pushed to your SIEM.
Deterministic rule execution
We do not rely on probabilistic models to block traffic. Enforcement is based on strict, deterministic regex and YARA signatures that you define.
Offline verifiable proof
Every decision is cryptographically signed using an Ed25519 key, tied to the exact policy version in force. Hand the bundle to an auditor to verify offline.
Mechanisms, not promises.
The concrete features that deliver control. For implementation details, refer to the technical brief.
No surveillance backlash
Govern the AI channel without a root certificate on a single laptop.
A floor you can name and rely on
The patterns you define are blocked deterministically — no model, no opinion.
Policy that reaches everyone, fast
Author once; the whole fleet enforces it in about ten seconds, tamper-proof.
A judge you supply — and pay nothing for
Weigh ambiguous content with your own model. On-prem capable.
Which decisions block, and which just advise
You always know whether a decision was a hard block or an advisory note.
Lands in the SIEM you already run
Splunk, Microsoft Sentinel, or syslog — your platform team writes no code.
Operator seats from your own directory
SSO and SCIM via your IdP — no separate user list to manage.
Device posture your IdP can read
Conditional access sees Tether's signal in a format it already understands.
Evidence your auditor verifies without you
Every decision proves which signed policy made it — checked offline.
"This isn't spyware."
Here's the part you can check yourself.
The fastest way to lose a room full of developers is to make this feel like surveillance. It doesn't, and nobody should have to take that on faith. Every claim below, a developer can check on their own machine.
- · No root certificate on your machine. Tether doesn't install a corporate CA, so it can't decrypt your banking session, your personal email, or anything else outside the AI routes. Check your trust store — nothing of ours is in it.
- · The proxy is loopback-only. It binds to
127.0.0.1by default; widening it takes explicit operator config and emits a named startup warning. Runnetstatand see for yourself. - · It doesn't read TLS-tunneled content. It classifies the destination and reads prompts only on the AI routes your org configured — not your general web traffic.
- · Safe work is never ticketed. The overwhelming majority of prompts pass silently. Only a named risk or a genuinely ambiguous moment ever surfaces a decision — there's no manager watching your ordinary work.
The loopback binding and route-scoped inspection are in the technical brief →
Clipboard, downloads, external links —
visible and recorded now, enforced next.
- · Visibility and audit on every workspace action. Clipboard, downloads, external links, screen capture, and coach mode all surface a decision and emit an event you can see.
- · VS Code extension. Shipped — identity sync, agent inventory, and opt-in coverage for the terminals VS Code spawns.
- · Cooperative-agent approvals. Agents that ask permission can route through the same just-in-time approval queue your operators already watch.
- · Managed IDE build. A signed installer for macOS, Windows, and Linux turns the advisory workspace controls into hard enforcement.
- · More editors. VS Code is shipped; Cursor and JetBrains are on the near-term roadmap.
- · Durable evidence retention. Tamper-evident, long-horizon retention of every signed policy version, for teams that need full forensic history.
The exact state of each workspace control — what's enforcing versus advisory, and the roadmap behind it — is in the technical brief →
A risky moment, governed —
without filing a developer ticket.
When a moment genuinely needs a human, the developer doesn't open a ticket and wait a day. The action pauses, an operator gets the context, and a decision comes back in seconds. Safe work never triggers any of this.
The developer stays in flow. The risky action pauses in place rather than failing or filing a ticket. Approve, and they continue immediately — no context switch, no support queue.
The operator gets what they need to decide. Who, what, and the matched policy land in one console view. The default target is a five-minute decision window, tunable to your team.
It's auditable either way. Approve, deny, or let it time out — every outcome is recorded, and you choose the safe default when no one answers in time.
Cooperative agents use the same lane. An AI agent that asks permission before acting routes into the very same approval queue your operators already watch — one console, one workflow.
See the operator decide in seconds on the demo → The request-and-decide machinery is in the technical brief →
"What about Cursor?"
How much Tether sees depends on the tool. Here's each one, specifically.
For the CLI agents and editors your developers actually live in — Claude Code, Codex CLI, Aider, Zed, Continue — Tether reads the full prompt and response and enforces against it. That's the deep-visibility case, and it covers the tools doing the heavy lifting.
For tools with an opaque path — Copilot's chat, Cursor's default flow on unmanaged devices — Tether still ties the activity to a person and a vendor and can block the destination, but it doesn't read prompt content it can't see. And every decision records how the agent was identified — explicitly, inferred from headers, or unattributed — so the audit distinguishes solid attribution from a guess.
Bring the two tools your developers use most. In the walkthrough we'll show you exactly what Tether sees on each — full content, or attribution-only — and where the gaps are, before you commit to anything.
The full per-tool coverage matrix — architecture, best tier, what's seen, and the gap for each — is in the technical brief →
Bring two tools.
We'll show you both tiers.
Bring the AI tool your developers use most and one you're considering. We'll show you what Tether sees on each — and what it doesn't.